top of page
perceptive_background_267k.jpg

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) onl…

Published:

26 april 2026 om 22:00:00

Alert date:

27 april 2026 om 17:03:10

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Email & Messaging

The Apache Camel Mail component contains a header injection vulnerability where the MailHeaderFilterStrategy only filters outbound headers but not inbound ones. This allows attackers to inject Camel-specific headers through email messages that can alter route behavior in downstream components like camel-bean, camel-exec, or camel-sql. The vulnerability affects Apache Camel versions 3.0.0 to 4.14.6 and 4.15.0 to 4.18.1. Users should upgrade to version 4.19.0 or appropriate LTS versions 4.18.1 or 4.14.6. This follows a similar pattern to previously addressed vulnerabilities in camel-undertow and broader incoming-header filters.

Technical details

Mitigation steps:

Affected products:

Apache Camel

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page